Guidelines for remote access VPNs
Review these guidelines before configuring and managing remote access VPN policies.
General guidelines
-
Ensure that only one administrator modifies the policy at a time. The web interface allows multiple concurrent sessions, but only the last saved configuration remains.
-
Ensure that you unassign the remote access VPN policy associated with a Firewall Threat Defense device before moving it to a different domain.
-
Verify the ciphers for the remote access VPN policy before deployment:
-
For SSL: Choose , edit a policy. From the left pane, click SSL > RA-VPN.
-
For IPsec-IKEv2: Choose , edit a remote access policy. Click the Advanced tab and from the left pane, choose IPsec.
-
-
Do not run curl commands, including HTTP HEAD requests, on the remote access VPN headend device because these commands are not supported.
-
Ensure third-party clients provide a valid user agent because the Firewall Threat Defense device rejects VPN sessions with a null user agent.
-
Configure browser proxy using FlexConfig.
-
When Bypass Access Control policy for decrypted traffic is disabled and a downloadable access control list (DACL) is applied, decrypted traffic is evaluated against the access control policy (ACP) first. Traffic permitted by the ACP is then evaluated against the DACL; traffic denied by the ACP is not evaluated further.
NAT guidelines
-
Verify the NAT rules on the Firewall Threat Defense device to ensure that they do not disrupt the remote access VPN traffic.
-
Enable route lookup for any NAT rule applied to a remote access VPN network that uses DHCP. This configuration ensures that the device identifies the correct egress interface for DHCP request forwarding.
Certificate guidelines
-
Install the identity certificate on the device before deploying the remote access VPN policy to the device.
-
Manually add client certificates to your clients. You cannot use SCEP or CA services to distribute certificates.
Secure Client guideline
Use only one Secure Client package on low-end Firewall Threat Defense devices to prevent memory exhaustion and continuous restarts.